VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3555 CVEsRSS

CVE-2026-28498High· 7.5PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. S…

▾ Midnightauthlib · authlibEPSS 0.26%via NVD
CVE-2026-27962Critical· 9.1PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that…

▾ Abyssalauthlib · authlibEPSS 0.52%via NVD
CVE-2026-3227Medium· 6.8PoC
6mo ago

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an au…

▾ Twilighttp-link · tl-wr802n_firmwareEPSS 1.8%via NVD
CVE-2026-31899High· 7.5PoC
6mo ago

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

▾ Midnightcairosvg · cairosvgEPSS 0.52%via OSV
CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-32247High· 8.1PoC
6mo ago

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

▾ Midnightgraphiti-core · graphiti-coreEPSS 0.48%via OSV
CVE-2026-3783Medium· 5.3PoC
6mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

▾ Twilighthaxx · curlEPSS 0.51%via NVD
CVE-2026-3805High· 7.5PoC
6mo ago

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

▾ Midnighthaxx · curlEPSS 0.95%via NVD
CVE-2026-23813Critical· 9.8PoC
6mo ago

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…

▾ Abyssalhpe · arubaos-cxEPSS 0.74%via NVD
CVE-2026-31844High· 8.8PoC
6mo ago

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…

▾ Midnightkoha · kohaEPSS 0.57%via NVD
CVE-2026-31900Critical· 9.8PoC
6mo ago

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…

▾ Abyssalblack · blackEPSS 0.64%via OSV
CVE-2025-70330Low· 3.3PoC
6mo ago

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds …

▾ TwilightEPSS 0.15%via NVD
CVE-2025-67038Critical· 9.8CISA KEVPoC
6mo ago

An issue was discovered in Lantronix EDS5000 2.1.0.0R3

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…

▾ Hadallantronix · eds5008_firmwareEPSS 19%via NVD
CVE-2026-23907Medium· 5.3PoC
6mo ago

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…

▾ Twilightapache · pdfbox-examplesEPSS 0.89%via NVD
CVE-2026-27280High· 7.8PoC
6mo ago

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

▾ Midnightadobe · dng_software_development_kitEPSS 0.26%via NVD
CVE-2026-26118High· 8.8PoC
6mo ago

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

▾ MidnightAzure · Azure.McpEPSS 0.86%via OSV
CVE-2026-27826High· 8.2PoC
6mo ago

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

▾ Midnightmcp-atlassian · mcp-atlassianEPSS 1.0%via OSV
CVE-2026-24294High· 7.8PoC
6mo ago

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.7%via NVD
CVE-2026-0846High· 8.6PoC
6mo ago

Arbitrary File Read via Absolute Path Input in nltk.util.filestring()

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…

▾ Midnightnltk · nltk/nltkEPSS 0.53%via CVEORG
CVE-2026-30928HighPoC
6mo ago

Glances Exposes Unauthenticated Configuration Secrets

Glances Exposes Unauthenticated Configuration Secrets

▾ Midnightglances · glancesEPSS 1.6%via OSV
CVE-2025-69219High· 8.8PoC
6mo ago

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

▾ Midnightapache-airflow-providers-http · apache-airflow-providers-httpEPSS 0.69%via OSV
CVE-2026-25604Medium· 5.4PoC
6mo ago

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

▾ Twilightapache · apache-airflow-providers-amazonEPSS 0.51%via NVD
CVE-2024-14027Medium· 5.5PoC
6mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…

In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…

▾ TwilightEPSS 0.21%via NVD
CVE-2026-29786Medium· 6.3PoC
6mo ago

node-tar is a full-featured Tar for Node.js

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…

▾ Twilightisaacs · tarEPSS 0.39%via NVD
CVE-2026-29780Medium· 5.5PoC
6mo ago

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

▾ Twilighteml-parser · eml-parserEPSS 0.18%via OSV
CVE-2026-0847High· 8.6PoC
6mo ago

Path Traversal in nltk/nltk

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fa…

▾ Midnightnltk · nltk/nltkEPSS 0.90%via CVEORG
CVE-2026-23231High· 7.8PoC
6mo ago

netfilter: nf_tables: fix use-after-free in nf_tables_addchain()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add())…

▾ MidnightLinux · LinuxEPSS 0.79%via CVEORG
CVE-2025-66024Critical· 9.0PoC
6mo ago

The XWiki blog application allows users of the XWiki platform to create and manage blog posts

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…

▾ Abyssalxwiki · blog_applicationEPSS 0.36%via NVD
CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

▾ Hadalcisco · secure_firewall_management_centerEPSS 88%via NVD
CVE-2026-0014Medium· 6.2PoC
7mo ago

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVEs tagged “exploit-available” — page 90 · VulnSea